chore(deps): Bump the python-runtime group with 4 updates - #176
Merged
Merged
Conversation
Bumps the python-runtime group with 4 updates: [ruff](https://github.com/astral-sh/ruff), [coverage](https://github.com/coveragepy/coveragepy), [pandas-stubs](https://github.com/pandas-dev/pandas-stubs) and [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python). Updates `ruff` from 0.16.7 to 0.16.8 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.7...0.16.8) Updates `coverage` from 7.16.0 to 7.16.1 - [Release notes](https://github.com/coveragepy/coveragepy/releases) - [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst) - [Commits](coveragepy/coveragepy@7.16.0...7.16.1) Updates `pandas-stubs` from 3.0.5.260730 to 3.0.5.260914 - [Changelog](https://github.com/pandas-dev/pandas-stubs/blob/main/docs/release_procedure.md) - [Commits](pandas-dev/pandas-stubs@v3.0.5.260730...v3.0.5.260914) Updates `claude-agent-sdk` from 0.2.152 to 0.2.154 - [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases) - [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md) - [Commits](anthropics/claude-agent-sdk-python@v0.2.152...v0.2.154) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-runtime - dependency-name: coverage dependency-version: 7.16.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-runtime - dependency-name: pandas-stubs dependency-version: 3.0.5.260914 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-runtime - dependency-name: claude-agent-sdk dependency-version: 0.2.154 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-runtime ... Signed-off-by: dependabot[bot] <support@github.com>
DoRmAmMu1997
self-requested a review
September 21, 2026 07:35
…-runtime-b22453635d
Dependabot bumps the requirement files and cannot see the second assertions
that exist so a version cannot move without a human reading the release notes.
Two tests were red on the bump; both are now green for reasons written down
rather than asserted.
ruff 0.16.7 -> 0.16.8 + .pre-commit-config.yaml
coverage 7.16.0 -> 7.16.1 (no second assertion)
pandas-stubs 3.0.5.260730 -> 3.0.5.260914
claude-agent-sdk 0.2.152 -> 0.2.154
RUFF. The hook rev is bumped with it, which is the whole point of
test_precommit_ruff_rev_matches_the_requirements_dev_pin. 0.16.8 changes ten
rules; every one of them is either unselected here or has zero trigger sites in
this tree. We select E,W,F,I,B,UP,C4,SIM,RUF at target-version py312, so:
flake8-type-checking's TC001/2/3 change is unselected AND gated on Python 3.15;
PTH103 is unselected. Of the selected ones, SIM117's new nested-`async with`
detection finds nothing (the repo contains no `async with` at all), UP035's
ByteString change nothing, UP040/046/047 nothing (no TypeVarTuple, no
ParamSpec) and they narrow output rather than widen it, RUF043 nothing (none of
the 95 `pytest.raises(match=)` sites uses `\Z`), RUF064's parent_mode nothing.
Not left as changelog reading: 0.16.8 was installed in isolation and RUN over
this exact post-merge tree -- all checks passed, same as 0.16.7.
COVERAGE. Two bug fixes. The `case _:` exclusion fix cannot change anything we
measure: the repo has no `case _:` anywhere. The other is CoverageData.update()
on an in-memory database, which the gate does not use. Effectively a no-op
here. NOTE: coverage is the one pin in this group with NO second assertion, so
this bump could have gone green with nobody reading it -- exactly the hole the
numpy comment in this file describes. Flagged for the operator rather than
closed unilaterally, since adding an assertion is a policy change, not a bump.
PANDAS-STUBS. The pandas release being described does not move (3.0.5 both
sides), so the matching-majors reason this pin exists for is untouched; only
the stub snapshot advances. Typing-only, so it was verified BEFORE the merge:
mypy checks all 80 source files against 3.0.5.260914 with ZERO errors in repo
code. The upstream change that could have reached us is "move stub-only helper
types to _stubs_only" (#1935), and nothing here imports `pandas._typing` or
`_stubs_only`. The comment records how to repeat that run and warns that
staging stubs on MYPYPATH makes mypy analyse the stub package itself and report
~24 errors inside it -- an artifact, not a signal.
CLAUDE-AGENT-SDK. 0.2.154 is a bundled-CLI bump only. 0.2.153 is the only one
with a Python surface: a `snapshot` field on `SystemPromptPreset` and a new
`SystemPromptCustom` TypedDict, both additive and both on the PRESET form of
system_prompt. We never use that form -- `_system_prompt_as_file` passes the
FILE form because the prompt is far past Windows' 32,767-character command-line
limit -- so it cannot reach this agent even as a default. What actually moved
is the bundled CLI, 2.1.259 -> 2.1.274, which is the part running the agent and
which CI never spawns. Standing check unchanged: confirm on the next PAPER
session that decisions still return ("SLHuntingAgent decision cost ~$..."). If
they stop, revert this pin first.
origin/main is merged in so CI validates the state that will actually land,
which matters here because a ruff minor can flag code that reached main after
Dependabot cut the branch.
Negative-tested 5 ways, all 5 caught: reverting either bumped pin, leaving the
ruff hook behind, moving the ruff requirement ahead of the hook, and loosening
a pin from == to >=. The control is the finding above -- silently reverting
coverage still PASSES, which is what makes the missing assertion real rather
than theoretical.
Gates: 606 master, 28 market-data-health, 1580 pytest, ruff 0.16.8 (the new
pin), mypy (80 files), compileall, bandit.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-runtime group with 4 updates: ruff, coverage, pandas-stubs and claude-agent-sdk.
Updates
rufffrom 0.16.7 to 0.16.8Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
Commits
62914c4Bump version to 0.16.8 (#28648)c47e0cd[ty] Bound aliased intersection expansion during inference (#28546)ff4747brenovate: update uv hashes correctly with setup-uv (#28621)94efeaa[ty] Compact reachable binding and declaration histories (#28349)50020fb[ty] Avoid storing constraint nodes twice (#28375)446bb68[ty] Compare bound-method receivers before signatures (#28384)304ab86[flake8-type-checking] Prefer lazy imports overTYPE_CHECKINGon 3.15+ (`...d940b24[ty] Watch script dependencies in CLI watch mode (#28125)fe9f065[flake8-tidy-imports] Addextend-banned-api(#28644)31131db[ty] Supporttype[A & B](#27124)Updates
coveragefrom 7.16.0 to 7.16.1Release notes
Sourced from coverage's releases.
Changelog
Sourced from coverage's changelog.
Commits
ccbb992docs: prep for 7.16.10697cccchore: make upgrade12f3595chore: bump docker/setup-qemu-action in the action-dependencies group (#2280)35b58d3fix: CoverageData.update() can be called twice on an in-memory database. #227992e1ce9chore: bump the action-dependencies group with 4 updates (#2278)bf07310build: quote var expansion (actionlint SC2086)3c434f5quality: use shellcheck-py to get shellcheck in GitHub CI632f397build: use .txt instead of .pip, even though it's a stupid extensionffc6a4atest: only run diff-cover on pull requests33553b3fix: exclude thecaseline when an irrefutable case body is excluded (#2269)Updates
pandas-stubsfrom 3.0.5.260730 to 3.0.5.260914Commits
6ad02beVersion 3.0.5.2609145533758Bumppyreflyversion (#1945)711cf2fBLD: temporarily pin pyright to 1.1.411 (#1942)507243eTST: nightly expectPandas4WarningforSeries.drop/renameinplaceand...a09e2edTYP: align Index subtraction overloads (#1938)156be75TST: add focused Period scalar subtraction tests (#1936)6b84c3aCLN: load tests._typing from pandas-stubs/_typing.pyi without file swap (#1930)14f8185TST: add focused Period scalar addition tests (#1933)0a77a3aTYP: move stub-only helper types to _stubs_only (#1935)a382437TYP: update stubs for ty 0.0.76 (#1932)Updates
claude-agent-sdkfrom 0.2.152 to 0.2.154Release notes
Sourced from claude-agent-sdk's releases.
Changelog
Sourced from claude-agent-sdk's changelog.
Commits
9d398b6docs: update changelog for v0.2.1542a5bdccchore: release v0.2.154efcd177chore: bump bundled CLI version to 2.1.274763922bdocs: update changelog for v0.2.153f706bfbchore: release v0.2.1530fc0940chore: bump bundled CLI version to 2.1.273e773e44Add snapshot option to system_prompt (#1268)46fe65fci: raise the PyPI pre-flight threshold to 49.5 GiB for now (#1267)be6d116test: use the haiku alias in test_set_model (#1266)b39b656chore: bump bundled CLI version to 2.1.272Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions